Introduction
IFA Connect Ltd (company no. 15993861) (“IFA Connect”, “we”, “us”) is committed to protecting your privacy and ensuring your personal data is handled securely and responsibly. This Privacy Policy outlines the types of data we collect, how we use and share it, and your rights under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
IFA Connect is the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office (ICO) under reference ZB918058.
Who this policy applies to
This policy applies to two groups of users:
- Clients (leads): individuals seeking financial advice who submit their details through our service.
- Advisers: FCA-regulated Independent Financial Advisers who register on our portal to receive client introductions.
What data we collect
Client data (collected during the enquiry and matching process): name, email address, phone number, age, occupation, city and region, pension and ISA pot sizes and providers, portfolio values, income goals for retirement, family situation and financial goals, enquiry notes describing your advice needs.
Adviser data (collected during registration and portal use): name, email address, phone number, firm name, FCA number, region, payment and billing information (processed by Stripe, not stored by us directly), credit purchase and transaction history.
Technical data (collected automatically): IP address, browser type and version, authentication session data, cookies necessary for the functioning of the portal.
Lawful basis for processing
We process personal data on the following legal bases:
- Contract: to provide our matching and lead-generation service to both clients and advisers.
- Legitimate interests: to operate, secure, and improve the portal, to prevent fraud, and to administer adviser accounts.
- Consent: for marketing communications, where applicable.
- Legal obligation: to comply with FCA recordkeeping requirements and tax obligations.
How we use your data
- Matching clients with advisers: to connect clients with FCA-regulated financial advisers suited to their needs.
- Communication: to contact clients via email or phone regarding enquiries, and to send advisers transactional notifications including lead alerts, purchase confirmations, and account updates.
- Portal operation: to manage adviser accounts, process credit purchases, and provide customer support.
- Security: to protect accounts through two-factor authentication, rate limiting, and fraud detection.
- AI-assisted support: the portal includes a chat assistant powered by Anthropic’s Claude. Conversations with the assistant are processed by Anthropic in accordance with their data processing terms. No client PII is passed to the assistant.
- Marketing: with your consent, we may send newsletters, promotional content, or information about relevant services. You can withdraw consent at any time.
How we share your data
With advisers: client data is shared with FCA-regulated financial advisers through the portal after the adviser purchases the lead using credits. Advisers access client details directly through the secure portal and downloadable PDF summaries.
With sub-processors: we use the following third-party services to operate the portal. Each processes data on our behalf under appropriate data processing agreements: Supabase (database hosting and authentication, servers in EU), Stripe (payment processing), Postmark (transactional email delivery), Vercel (application hosting), Anthropic (AI chat assistant), Monday CRM (client relationship management and lead tracking).
We do not sell your data to any third party. Data is only shared as described above and is never distributed to unauthorised third-party providers.
International data transfers
Some of our sub-processors (Stripe, Vercel, Postmark, Anthropic) are based in the United States. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the ICO.
Data retention
We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy:
- Client lead data: retained for up to 6 years from the date of the enquiry, in line with FCA recordkeeping requirements.
- Adviser account data: retained for the duration of the account and for up to 6 years after closure for tax and regulatory compliance.
- Transaction and billing records: retained for 6 years in line with HMRC requirements.
- Technical logs: retained for up to 12 months for security and debugging purposes.
After the retention period, data is securely deleted or anonymised.
Your rights
Under the UK GDPR, you have the following rights:
- Right to access: you can request a copy of the personal data we hold about you.
- Right to rectification: you may request corrections to incomplete or inaccurate data.
- Right to erasure: you have the right to request the deletion of your personal data, subject to our legal retention obligations.
- Right to restrict processing: you can ask us to limit how we use your data in certain circumstances.
- Right to data portability: you can request your data in a structured, commonly used format.
- Right to object: you can object to the processing of your data where we rely on legitimate interests.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at hello@ifaconnect.co.uk. We will respond within one calendar month. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ico.org.uk).
Cookies
The portal uses cookies that are strictly necessary for authentication and security, including session cookies and two-factor authentication tokens. We also use analytical cookies to understand how the portal is used. By using the portal, you agree to the use of these cookies. You can manage cookie preferences through your browser settings.
Security measures
We take the protection of your personal data seriously and implement robust security measures, including:
Two-factor authentication (email verification codes and optional TOTP) on all portal accounts. Encrypted sessions using signed JSON Web Tokens. Bcrypt password hashing. Row-level security policies on our database ensuring users can only access data they are authorised to view. Rate limiting on authentication and sensitive endpoints. HTTPS encryption on all connections. Secure, HttpOnly, SameSite cookies to prevent session hijacking. Regular security audits of the portal codebase.
Data held on Monday CRM is protected with multi-factor authentication and access controls.
Data breach procedures
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay, in accordance with UK GDPR Article 33 and 34.
Children’s data
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
Third-party links
The portal may contain links to external websites. We are not responsible for the privacy practices of third-party sites and encourage you to read their privacy policies.
Changes to this policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically.
Contact information
If you have any privacy-related questions, concerns, or requests, please contact us at:
IFA Connect Ltd
Email: hello@ifaconnect.co.uk
ICO Registration: ZB918058
Governing law
This Privacy Policy is governed by and interpreted in accordance with the laws of the United Kingdom.
Last updated: July 2026